5.8 Ensure the Mailbox Access by Non-Owners Report is reviewed at least biweekly

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

You should review the Mailbox Access by Non-Owners report at least every other week. This report shows which mailboxes have been accessed by someone other than the mailbox owner.

NOTE: This setting is only available in the classic Exchange Admin center.

Rationale:

While there are many legitimate uses of delegate permissions, regularly reviewing that access can help prevent an external attacker from maintaining access for a long time, and can help discover malicious insider activity sooner.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the report, perform the following steps using the Microsoft 365 Admin Center:

Click Exchange.

Click on Classic Exchange admin center.

Click Compliance Management and auditing.

Select Run a non-owner mailbox access report.

Enter Start Date and End Date.

Change Search for access by field to all non-owners.

Select Search.

See Also

https://workbench.cisecurity.org/files/3729